rails / webpacker

Use Webpack to manage app-like JavaScript modules in Rails
MIT License
5.31k stars 1.47k forks source link

Security Vulnerability for postcss #3321

Open aashishpsaini opened 9 months ago

aashishpsaini commented 9 months ago

We get 78 vulnerabilities for postcss of Moderate severity which is a dependency of webpacker. Even after upgrading postcss to 8.4.31 yarn-audit still gives the vulnerabilities. Here is a part of the log:

image

More details here: https://github.com/advisories/GHSA-7fh5-64p2-3v2j